





Remote and recognizable employer increase applicant density, but niche GRC/AI risk skills and seniority limit competition.
Requires specialized GRC, security, and AI-risk experience, so cross-industry transferability is limited.
Explicit 6+ years, mandatory GRC platform/tool experience, audit support and specialized AI-risk skills create strict filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Design, implement, and mature a quantitative-leaning enterprise risk management program across information security, AI, and operational risk.
Own and maintain a live enterprise risk register with documented owners, risk scoring, treatment decisions, and remediation timelines, driving actionable risk intelligence.
Leverage AI tools to augment risk monitoring, analysis, narrative drafting, and early detection of emerging risks; support third-party risk management assessments.
6+ years in GRC, information security, risk management, or IT audit, preferably in SaaS/cloud-native environments.
4+ years hands-on experience building or maturing risk registers and scoring methodologies with quantitative risk measurement.
Strong knowledge of security and compliance frameworks including SOC 2, ISO 27001, NIST CSF 2.0; familiarity with AI risk frameworks (ISO 42001, NIST AI RMF).
Proficiency with GRC platforms (Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent) and experience supporting external audits and vendor risk assessments.
Experienced in transitioning risk programs from qualitative to data-driven, quantitative risk measurement with scoring models and live data reporting.
Skilled at integrating AI tooling responsibly into risk workflows to improve risk identification, narrative, and reporting while validating outputs.
Comfortable translating complex technical risk data into clear business impact language suitable for engineers up to board-level executives and managing cross-functional stakeholders.